Skip to main content
Tanqory IconTanqory Logo
Log In
Get Started
  • Home
  • Why Tanqory
  • Pricing
  • Partners
  • Themes
  • App Store
  • Academy
  • Affiliates
  • Community
  • Developers
  • Support
  • Business Tools
  • News
  • Research
  • Blog
  • Engineering
  • Legal
  • Status
  • Build & Launch
  • Sell & Get Paid
  • Market & Engage
  • Ship & Deliver
  • Operate & Control
  • Go Global
  • Platform Overview
  • Commerce Core
  • Builder
  • Creative & Brand
  • Intelligence & Automation
  • Operations
  • Integrations
  • Industries overview
  • E-commerce & Retail
  • Wholesale & B2B
  • Restaurants
  • Events & Ticketing
  • Health & Wellness
  • Services
  • About
  • Executive
  • Leadership
  • Governance
  • Brand Identity
  • Careers
  • Legal
October 12, 2024whats-new-at-tanqory

Enhanced Multi-Factor Authentication Options

New MFA options including hardware keys, biometrics, and authenticator apps.

Try Tanqory
Multi-factor authentication methods

Protect your account with our comprehensive suite of enhanced multi-factor authentication options, designed to provide maximum security without compromising user experience.

The Passwordless Future Is Here

Passwords alone are no longer sufficient. With cyber threats evolving daily, multi-factor authentication has become essential for protecting your digital identity. We're excited to announce expanded MFA options that leverage the latest security technologies while remaining easy to use.

The passwordless authentication market is growing from $22.14 billion in 2025 to an expected $61.45 billion by 2032, reflecting the industry-wide shift toward more secure authentication methods. Gartner projects that by 2025, over 50% of workforce authentication transactions will be passwordless, and we're proud to be leading this transformation.

Comprehensive MFA Options

Hardware Security Keys: FIDO2/WebAuthn Support

Hardware security keys represent the gold standard in authentication security. Our platform now fully supports FIDO2 and WebAuthn standards, allowing you to use physical security keys for phishing-resistant authentication.

Why Hardware Keys?

  • Phishing-Resistant: Impossible to trick users into providing credentials to fake websites
  • Fast Authentication: Three times faster than traditional passwords
  • No Shared Secrets: Cryptographic keys never leave your device
  • Universal Compatibility: Works across all major browsers and platforms
  • Long-Lasting: Hardware keys can last years without replacement

Supported Devices:

  • YubiKey 5 Series
  • Google Titan Security Keys
  • Feitian ePass FIDO security keys
  • Thetis FIDO U2F security keys
  • Any FIDO2-certified security key

How It Works: Hardware keys use public-key cryptography. When you register a key, a unique cryptographic key pair is created. The public key is stored on our servers, while the private key remains securely on your hardware device. Authentication happens through a cryptographic challenge-response process that proves you possess the physical key without ever transmitting the private key itself.

Best Practices:

  • Register multiple keys for redundancy
  • Keep a backup key in a secure location
  • Use keys with NFC for mobile device compatibility
  • Consider keys with biometric capabilities for additional security
  • Store keys separately from devices they protect

Biometric Authentication: Face ID and Fingerprint

Leverage the biometric sensors already built into your devices for seamless, secure authentication. Our biometric support works with Face ID, Touch ID, Windows Hello, and Android biometric systems.

Advantages:

  • Convenience: Authenticate with a glance or touch
  • Speed: Eight times faster than password plus traditional MFA
  • Unique to You: Biometric data is nearly impossible to replicate
  • On-Device Processing: Biometric data never leaves your device
  • Accessibility: Easier for users with mobility or memory challenges

Security Architecture: We implement biometric authentication using WebAuthn, which means your actual biometric data never leaves your device. Instead, the authentication process uses cryptographic proofs that work with your device's secure enclave or trusted platform module (TPM). Your fingerprint or face data remains stored securely on your device, and we only receive confirmation that authentication succeeded.

Platform Support:

  • iOS/iPadOS: Face ID and Touch ID on supported devices
  • macOS: Touch ID on MacBook and Magic Keyboard
  • Windows: Windows Hello facial recognition and fingerprint
  • Android: Fingerprint and facial recognition on supported devices

Privacy Guarantees:

  • Biometric data never transmitted over the network
  • Authentication uses cryptographic tokens, not biometric templates
  • Compliance with GDPR, CCPA, and biometric privacy regulations
  • Users maintain complete control over biometric enrollment
  • Option to disable biometrics at any time

Authenticator Apps: TOTP Support

Time-based One-Time Passwords (TOTP) provide a reliable, widely-supported MFA method that works offline and doesn't require specialized hardware.

How TOTP Works: When you enable TOTP authentication, you scan a QR code with your authenticator app. This establishes a shared secret between your account and the app. The app then generates time-synchronized six-digit codes that change every 30 seconds. You enter the current code when logging in to prove you have access to your registered device.

Recommended Authenticator Apps:

  • Authy: Multi-device sync with encrypted backups
  • Google Authenticator: Simple, reliable, widely used
  • Microsoft Authenticator: Integrates with Microsoft ecosystem
  • 1Password: Combines password management with TOTP
  • Duo Mobile: Enterprise-grade with push notifications
Enhanced Multi-Factor Authentication Options - Content image

Advantages:

  • Works offline without network connectivity
  • No dependency on SMS or phone service
  • Supported on all smartphones and tablets
  • Can be backed up for device migration
  • Industry-standard implementation

Setup Process:

  1. Enable TOTP in your security settings
  2. Scan the QR code with your authenticator app
  3. Enter the six-digit verification code
  4. Save your backup codes in a secure location
  5. Confirm TOTP is active in your security settings

Backup Codes: Emergency Access

We provide backup codes as a safety net for situations where your primary MFA methods aren't available.

When to Use Backup Codes:

  • Lost or damaged security key
  • New phone without authenticator app
  • Traveling without biometric-enabled devices
  • Emergency access situations
  • Device replacement or upgrades

Security Best Practices:

  • Generate Fresh Codes: Create new codes after any use
  • Secure Storage: Keep codes in a password manager or secure physical location
  • Limited Use: Each code can only be used once
  • Regeneration: Generate new codes if you suspect compromise
  • Multiple Sets: Consider keeping backup codes in multiple secure locations

How Many Codes? We provide 10 single-use backup codes when you enable MFA. Once a code is used, it's immediately invalidated. You can generate new sets of codes at any time from your security settings.

The Technology: FIDO2 and WebAuthn

Understanding FIDO2

FIDO2 (Fast Identity Online 2) is an open authentication standard that enables passwordless and multi-factor authentication through public-key cryptography. It consists of two main components:

WebAuthn (Web Authentication API): A web standard that enables websites and applications to offer passwordless and multi-factor authentication using public-key cryptography. WebAuthn is supported by all major browsers including Chrome, Firefox, Safari, and Edge.

CTAP (Client to Authenticator Protocol): Enables external authenticators like security keys to communicate with devices over USB, NFC, or Bluetooth.

Quantum-Safe Security

In a significant 2025 development, FIDO2 and passkeys have become quantum-resistant. On April 24, 2025, IANA updated the CBOR Object Signing and Encryption (COSE) codelist to officially support post-quantum cryptographic (PQC) algorithms. This means our authentication system is prepared to resist threats from quantum computers, ensuring your accounts remain secure even as computing technology advances.

Industry Adoption

We're part of a growing movement toward more secure authentication:

  • Nearly half (48%) of the top 100 websites now offer passkeys as a login method
  • E-commerce platforms are driving passkey adoption, accounting for nearly half of all passkey authentications
  • Major organizations have deployed hundreds of thousands of security keys to their workforce
  • Consumer awareness is growing, with 53% recognizing stronger security and 54% appreciating greater convenience

Performance and User Experience

Speed Improvements

Our new MFA methods are significantly faster than traditional authentication:

  • Passkey logins: 3x faster than passwords
  • Compared to password + traditional MFA: 8x faster
  • Biometric authentication: Sub-second authentication times
  • Hardware keys: Tap and authenticate in under 2 seconds
Enhanced Multi-Factor Authentication Options - Slide 1
Enhanced Multi-Factor Authentication Options - Slide 2
Enhanced Multi-Factor Authentication Options - Slide 3

Reduced Friction

We've designed our MFA implementation to be as seamless as possible:

  • Contextual Prompts: Only request MFA when necessary
  • Device Trust: Remember trusted devices for convenience
  • Adaptive Authentication: Risk-based authentication that requires additional verification only when needed
  • Multiple Methods: Choose the authentication method that works best for each situation
  • Progressive Enrollment: Gradually guide users through MFA setup

Implementation and Rollout

Getting Started

Enabling MFA is straightforward:

  1. Navigate to Security Settings: Find MFA options in your account security settings
  2. Choose Your Method: Select from hardware keys, biometrics, authenticator apps, or multiple methods
  3. Follow Setup Instructions: Each method has guided setup with clear instructions
  4. Generate Backup Codes: Save backup codes in a secure location
  5. Test Your Setup: Verify everything works before completing setup

Organizational Rollout

For team administrators, we provide tools to manage MFA across your organization:

Admin Controls:

  • Enforcement Policies: Require MFA for all team members
  • Method Requirements: Specify which MFA methods are acceptable
  • Grace Periods: Give users time to set up MFA before enforcement
  • Reporting: Track MFA adoption across your organization
  • Support Resources: Help team members enable and use MFA

Best Practices for Teams:

  • Communicate the change well in advance
  • Provide clear documentation and training
  • Offer multiple authentication methods
  • Designate internal champions to help others
  • Monitor adoption and provide support
  • Consider providing hardware keys to team members

Migration from Legacy MFA

If you're currently using SMS-based authentication, we encourage upgrading to more secure methods:

Why Move Beyond SMS:

  • SMS is vulnerable to SIM swapping attacks
  • Phone number portability creates security risks
  • SMS doesn't work in areas without cellular coverage
  • SMS is being deprecated by security standards
  • Modern alternatives are more secure and convenient

Migration Path:

  1. Add a new MFA method (hardware key, biometric, or authenticator app)
  2. Test the new method thoroughly
  3. Remove SMS as your primary MFA method
  4. Keep backup codes updated
  5. Consider registering multiple MFA methods for redundancy

Security Considerations

Defense in Depth

MFA is one layer in our comprehensive security strategy:

  • Encryption: All data encrypted in transit and at rest
  • Session Management: Secure session handling with automatic timeouts
  • Anomaly Detection: AI-powered detection of unusual authentication patterns
  • Audit Logs: Comprehensive logging of all authentication events
  • Regular Security Audits: Third-party penetration testing and security assessments

Compliance and Standards

Our MFA implementation meets or exceeds requirements for:

  • NIST 800-63B: Digital identity guidelines
  • PCI DSS: Payment card industry standards
  • HIPAA: Healthcare information security
  • SOC 2 Type II: Service organization controls
  • GDPR: European data protection regulation
  • CCPA: California consumer privacy act
  • ISO 27001: Information security management

Threat Protection

Our MFA methods protect against:

  • Phishing: Hardware keys and WebAuthn are phishing-resistant
  • Credential Stuffing: Stolen passwords are useless without second factor
  • Man-in-the-Middle: Cryptographic authentication prevents interception
  • Brute Force: Rate limiting and account lockouts
  • Social Engineering: Physical tokens can't be tricked out of users
  • SIM Swapping: No reliance on phone numbers

Support and Resources

Documentation

Comprehensive guides available for:

  • Setting up each MFA method
  • Troubleshooting common issues
  • Best practices for security
  • Organizational deployment guides
  • API documentation for developers

Getting Help

Support Channels:

  • In-app help and guided setup
  • Video tutorials for each method
  • Live chat support for setup assistance
  • Email support at security@tanqory.com
  • Community forums for peer advice

Common Questions:

  • What if I lose my security key?
  • How do I set up MFA on multiple devices?
  • Can I use different methods on different devices?
  • What happens if my phone with authenticator app breaks?
  • How do I help team members with MFA setup?

Looking Ahead

Future Enhancements

We're continuously improving our authentication capabilities:

Coming Soon:

  • Passkey Sync: Sync passkeys across your devices
  • Risk-Based Authentication: Adaptive MFA based on login context
  • Behavioral Biometrics: Continuous authentication based on usage patterns
  • Hardware Key Management: Centralized management for organizational hardware keys

Industry Leadership

We're committed to advancing authentication security:

  • Active participation in FIDO Alliance
  • Contributing to WebAuthn standards development
  • Publishing security research and best practices
  • Partnering with hardware key manufacturers
  • Supporting emerging authentication technologies

Take Action Today

Security is a shared responsibility. Enable multi-factor authentication today to protect your account and data.

Recommended Setup:

  1. Primary: Hardware security key or biometric authentication
  2. Secondary: Authenticator app as backup
  3. Emergency: Backup codes stored securely
  4. Review: Check your security settings quarterly

Two factors are better than one. Multiple secure factors are even better.

For security questions, contact security@tanqory.com To report security issues, visit security.tanqory.com

Author:Tanqory Team
Published:October 12, 2024
Topic:whats-new-at-tanqory

Keep Reading

Bug bounty program dashboard

Expanding Our Bug Bounty Program

whats-new-at-tanqory · Oct 16, 2024

Affiliate partner growth planning

Tanqory Affiliate Referral Guide

whats-new-at-tanqory · Aug 3, 2025

Affiliate partner growth planning

Tanqory Affiliate FAQ

whats-new-at-tanqory · Jul 14, 2025

Ready to build your store?

Why Tanqory

  • Why Tanqory
  • Pricing
  • AI Platform
  • Infrastructure & Security
  • Global Commerce
  • Enterprise
  • Services

Products

  • Platform overview
  • Builder
  • Commerce Core
  • Creative & Brand
  • Operations
  • Intelligence & Automation
  • Integrations

Solutions

  • Solutions overview
  • Build & Launch
  • Sell & Get Paid
  • Market & Engage
  • Ship & Deliver
  • Operate & Control
  • Go Global

Industries

  • Industries overview
  • E-commerce & Retail
  • Wholesale & B2B
  • Restaurants & Café
  • Health & Wellness
  • Events & Ticketing
  • Services & Appointments

Company

  • About Us
  • Executive
  • Leadership
  • Governance
  • Brand Identity
  • System Status

Careers

  • Open Positions

Legal

  • Legal

Support

  • Help Center
  • Community Forum
  • Events

Developers

  • Developer Resources
  • API Documentation

Learn & Partners

  • Online Academy
  • Affiliates Program

Research

  • Publications

Blog

  • Start & Build

Legal

  • Legal Overview
  • Trust & Security

Themes

  • All Themes
© 2025-2026 Tanqory Inc.
Terms of UsePrivacy Policy
  • Home
  • Why Tanqory
  • Pricing
  • Partners
  • Themes
  • App Store